CVE-2018-13442: SolarWinds Network Performance Monitor
High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.
SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames parameter.
Affected products
- SolarWinds Network Performance Monitor: up to and including 12.3
Published 2019-07-16. Last modified 2026-06-17.